
Welcome to Lesson 9! After a brief break for the May holidays, we continue our publications. Today, we will discuss a no less interesting topic, namely — Application Control and URL Filtering. This is what Check Point is sometimes purchased for. Need to block Telegram, TeamViewer, or Tor? That's what Application Control is for. Additionally, we will touch upon another interesting blade — Content Awareness, and we will also discuss the importance of HTTPS Inspection. But let's take it step by step!
As you may remember, in Lesson 7, we began discussing Access Control policy, but so far we have only covered the Firewall blade and played a bit with NAT. Now, we will add three more blades — Application Control, URL Filtering and Content Awareness.
Application Control & URL Filtering
Why do I consider App Control and URL Filtering together in one lesson? This is not without reason. In fact, it has become quite difficult to clearly delineate where an application ends and a simple website begins. Take Facebook, for example. What is it? A website? Yes. But it contains many micro-applications. Games, videos, messages, widgets, etc. And all of this ideally needs to be managed. This is exactly why App Control and URL Filtering are always activated together.
Now, regarding the database of applications and websites. You can view them in SmartConsole via Object Explorer. There is a special filter for this — Applications/Categories. Furthermore, there is a special resource — . You can always check if a particular application (or resource) is in Check Point's database.

There is also a service , where you can always verify which "Check Point" category a particular resource belongs to. You can even request a change of category if you believe it is incorrectly assigned.

In other respects, everything with these blades is quite straightforward. You create an access list, specify the resource/application that needs to be blocked or, conversely, allowed. That's all there is to it. We will see this in practice a bit later.
Content Awareness
I see no reason to repeat this topic within our course. I detailed this blade quite thoroughly in the previous course — .
HTTPS Inspection
Similarly with HTTPS inspection. I elaborated both the theoretical and practical parts of this mechanism quite well here — However, HTTPS inspection is important not only for security but also for accurately identifying applications and websites. This is discussed in the video lesson below.
Video lesson
In this lesson, I will thoroughly explain the new concept of Layers, create a simple policy to block Facebook, implement a restriction on downloading executable files (using Content Awareness), and show how to enable HTTPS inspection.

Stay tuned for more and join our 🙂
Source: habr.com
